You should be able to use a Dynamic Access Policy (DAP) setup to first check for the machine certificate. Then further configure the profile to check for user certificate plus the RADIUS OTP authentication.
I believe it will require Anyconnect Premium license to use DAP.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...